A patient moves between a primary care office, a specialist, a hospital, and a pharmacy, and at each stop the information generated at the previous stop often fails to follow them. Data sharing between healthcare entities is only clinically useful when the right information reaches the right party, in a usable and secure form, at the moment it is needed. The scale of this problem has been measured directly: health policy research has found that the average Medicare beneficiary sees roughly two primary care physicians and five specialists spread across four or more different practices annually, and a meaningful share of those visits occur without the treating clinician having full visibility into care delivered elsewhere, a gap health economists have linked to tens of billions of dollars in unnecessary duplicate testing and avoidable complications every year.
The push to fix this has been backed by substantial federal investment and regulatory pressure. Since 2009, the HITECH Act has channeled more than $35 billion in incentive payments toward EHR adoption, and the 2016 21st Century Cures Act introduced information blocking rules, now actively enforced, that prohibit healthcare organizations and technology vendors from unreasonably interfering with the flow of electronic health information. Despite this investment, ONC survey data has repeatedly found that only a fraction of hospitals report being able to routinely find, send, receive, and integrate outside patient data across all four of these dimensions simultaneously, illustrating just how much daily friction persists even after more than fifteen years of coordinated federal policy effort.
Who Needs to Share Healthcare Data?
Physicians need information from specialists and hospitals to manage ongoing care. Hospitals need outside records during admissions to avoid duplicating tests and to understand a patient’s full history. Specialists need referral information and prior test results before a consultation.
Pharmacies need accurate, current prescription information. Laboratories and imaging providers need to route results back to ordering physicians reliably. Payers need claims data to process coverage decisions. Public health agencies need aggregated, often de-identified data to track disease trends. Patients need access to their own complete record, and researchers need structured data to study population health questions.
Each of these parties has a distinct purpose for the same underlying information, which is part of why a single one-size-fits-all sharing arrangement rarely works well across the entire healthcare ecosystem.
What Good Data Sharing Looks Like From the Patient’s Perspective
In an emergency, good data sharing means a treating physician can quickly see allergies and current medications even without a prior relationship with that hospital. During a specialist referral, it means relevant history and recent test results arrive without the patient having to manually collect and hand-carry records.
For medication reconciliation, it means every prescriber can see the patient’s complete current medication list, reducing dangerous interactions, a genuinely high-stakes concern given that adverse drug events tied to incomplete medication information are estimated to contribute to well over 100,000 emergency department visits annually among older adults alone.
During care transitions, such as a hospital discharge to home health services, it means the receiving provider has the discharge summary before the patient even arrives. When changing providers entirely, it means new records transfer without lengthy manual requests, a process that historically, and still today in a meaningful share of cases, involves fax transmission; remarkably, fax machines remain in active use for at least some record transfers across a majority of U.S. hospitals even now. Through a patient portal, it means the patient themselves can view and share their own information as needed.
Why Healthcare Data Sharing Still Fails
Legacy systems built before modern data standards existed often cannot easily connect to newer platforms. Incompatible formats between different vendors’ systems create friction even when both sides want to share data. Terminology differences mean the same clinical concept can be coded differently across systems, causing meaning to get lost even when data technically transfers.
Data quality problems, such as incomplete or inconsistent entries, undermine the value of whatever does get shared. Identity matching errors can link one patient’s data to another patient’s record; research on patient matching accuracy has found error rates ranging from under 1 percent within a single well-maintained system to more than 20 percent when matching patients across different, unaffiliated organizations, a gap that becomes a serious patient safety concern at scale. Organizational incentives do not always align, since some entities have historically had limited motivation to share data freely with competitors. Workflow limitations, privacy and security concerns, and contractual or technical barriers between vendors round out the list of persistent obstacles.
The Infrastructure Behind Modern Health Data Exchange
Application programming interfaces allow different systems to request and exchange data in a structured way. FHIR provides a widely adopted standard for how that health data should be formatted during exchange, and adoption has accelerated considerably since ONC’s 2020 Cures Act final rule required certified EHR technology to support FHIR-based APIs, a requirement that has pushed the large majority of U.S. hospitals to stand up FHIR-enabled patient access endpoints within just a few years. Health information exchanges operate as regional or state-level networks connecting participating organizations, while health information networks extend this concept more broadly.
TEFCA, the Trusted Exchange Framework and Common Agreement, functions as a nationwide framework intended to connect these networks together rather than requiring every organization to negotiate separate bilateral agreements. USCDI defines the standardized set of data elements systems are expected to be able to exchange, giving participating organizations a common target to build toward, with the dataset’s scope expanding through annual updates as ONC incorporates new categories like clinical notes and social determinants of health.
Secure Sharing Requires More Than Encryption
Strong authentication confirms that both the system and the person requesting data are legitimate. Authorization determines what a specific user or system is permitted to access. Access governance structures define who is responsible for granting and reviewing that access over time.
Audit trails create accountability by recording every access and disclosure. Data minimization limits what is shared to what is actually necessary for the purpose at hand. Consent mechanisms, where relevant, respect patient preferences. Network security protects the technical infrastructure itself, vendor governance ensures third parties meet the same standards as the primary organizations, and incident response planning determines how quickly problems get identified and addressed when they occur.
Interoperability and Information Blocking
Information blocking refers to practices that unreasonably interfere with the access, exchange, or use of electronic health information when data sharing is otherwise appropriate and permitted. Federal policy in this area, maintained through current ONC materials, distinguishes between legitimate security or privacy constraints on data sharing and unnecessary barriers erected for other reasons, such as competitive advantage.
Since enforcement began, HHS has processed thousands of information blocking complaints, with penalties for confirmed violations by health IT developers reaching up to $1 million per violation, a meaningful deterrent that has pushed vendors to reconsider data-sharing restrictions that might previously have gone unchallenged.
This distinction matters because not every restriction on data sharing is inappropriate. A legitimate privacy concern or a genuine security limitation is different from a barrier imposed simply to keep patients within one organization’s network.
Measuring Whether Data Sharing Is Actually Working
| Metric | What it reveals |
|---|---|
| Successful exchange rate | How often requested data actually arrives |
| Time to information availability | How quickly shared data reaches the requesting party |
| Data completeness | Whether shared records contain the full expected information |
| Duplicate testing | Whether missing information leads to repeated tests |
| Referral completion | Whether referrals result in the intended consultation with adequate information |
| Medication reconciliation accuracy | Whether medication lists match across providers |
| Patient access | Whether patients can view and use their own records easily |
| Clinician usability | Whether shared data is presented in a way clinicians can efficiently use |
Tracking these metrics reveals whether interoperability investments are translating into real operational improvement, rather than simply checking a technical compliance box.
The Future of Healthcare Data Sharing
Nationwide exchange through frameworks like TEFCA, more standardized APIs built on FHIR, patient-centered data access that gives individuals more direct control, deeper integration with public health reporting systems, expanded research use of aggregated data, and more connected medical devices feeding data directly into shared records all represent directions this space continues to move toward. TEFCA’s Qualified Health Information Networks, first operational in the mid-2020s, have expanded participation to cover a rapidly growing share of hospitals and providers nationwide, suggesting the “network of networks” model may finally be closing the gap between policy ambition and everyday clinical reality.
Progress depends on sustained investment from healthcare organizations, continued standards development, and policy frameworks that balance broader access with appropriate privacy and security protections. Health economists estimate that fully realized interoperability could save the U.S. healthcare system tens of billions of dollars annually through reduced duplicate testing, fewer preventable readmissions, and less administrative burden spent chasing down records that should have simply been available already.
None of this implies unrestricted access to all patient information by anyone connected to a network; it means building systems where appropriate information reaches appropriate parties reliably and securely, a goal that remains more achievable today than at any point in the past, even as it continues to require sustained effort across thousands of independently operated healthcare organizations nationwide.
FAQ
Q: Why is healthcare data sharing important?
A: It reduces duplicated testing, prevents dangerous medication gaps, speeds up emergency care, and supports better-coordinated treatment across multiple providers.
Q: Who can share healthcare data?
A: Physicians, hospitals, specialists, pharmacies, laboratories, payers, public health agencies, and patients themselves can all participate in data sharing, depending on applicable rules and agreements.
Q: What prevents healthcare organizations from sharing data?
A: Common barriers include legacy systems, incompatible data formats, terminology differences, misaligned organizational incentives, and privacy or security concerns.
Q: What is a health information exchange?
A: It is a network, often regional or state-level, that connects participating healthcare organizations to enable secure exchange of patient health information.
Q: What role does FHIR play?
A: FHIR provides a standardized format for structuring and exchanging health data, making it easier for different systems to communicate through APIs.
Q: What is TEFCA?
A: TEFCA is a nationwide framework designed to connect regional health information networks, functioning as a network of networks for secure data exchange.
Q: How can healthcare data be shared securely?
A: Through strong authentication, access governance, encryption, audit trails, data minimization, and clear agreements between participating organizations.
Q: Does HIPAA prevent healthcare data sharing?
A: No. HIPAA permits data sharing for treatment, payment, and healthcare operations, and establishes safeguards for how that sharing should occur rather than prohibiting it outright.